Skip to main content

Overview

Privacy isn't a checkbox. It's a commitment. Sally AI is built on the principle that your data belongs to you: it stays within the EU, primarily in Germany at Hetzner, is masked before any AI model ever touches it, and is never used to train or improve language models. We hold ourselves to the highest European data protection standards so you can focus on getting value from AI, without compromise.

Last updated: 07.05.2026·All documents current

Compliance & Certifications

GDPRGDPR
Compliant

Fully compliant with the EU General Data Protection Regulation. GDPR-compliant DPA under Art. 28 with every customer.

Germany HostingGermany Hosting
Active100% DE by end of May 2026

All data is stored in the EU, primarily in Germany at Hetzner. No third-country transfers, ever. From end of May 2026, exclusively in German data centers at Hetzner.

Data MaskingData Masking
Active

All personal data is masked before being processed by any language model. Identifiable information never reaches the AI.

ISO 27001ISO 27001
CompliantCertified as of June 2026

Hosted in ISO 27001-certified EU data centers. Security management aligned with ISO 27001 principles.

ISO 14001ISO 14001
CompliantCertified as of June 2026

Environmental management system per ISO 14001. We are committed to sustainable operations and continuous improvement of our environmental performance.

ISO 9001ISO 9001
CompliantCertified as of June 2026

Quality management system per ISO 9001. Our processes are systematically monitored and continuously improved.

SOC 2SOC 2
Compliant

Service organization controls aligned with SOC 2 principles for security, availability, and confidentiality.

No AI Training
Guaranteed

Your data is never used to train or improve language models, guaranteed contractually and technically.

Roadmap
Our path to GDPR & Compliance
May 2026🇩🇪 100% Germany-only infrastructure

All data exclusively in German data centers, with zero dependency on non-German EU regions.

June 2026ISO 27001 certification

We are actively working toward ISO 27001 certification (currently: certified infrastructure).

June 2026ISO 14001 certification

We are actively working toward ISO 14001 certification for sustainable environmental management.

June 2026ISO 9001 certification

We are actively working toward ISO 9001 certification for systematic quality management.

Sep 2026Network segmentation & dedicated bastion host

Network-level separation of administration traffic and compute workload networks, including a dedicated jump/bastion host (per BSI C5:2026, controls COS-02.01B, COS-05.01B, COS-05.02B).

⚖️
EU AI Act
Regulation (EU) 2024/1689
Risk Classification
Limited Risk
Transparency
Auto-notice in meeting chat
Data Masking
Before every LLM call
Declaration
Available for download
Full details →

Security Controls

Infrastructure
  • AES-256 encryption at rest
  • TLS/SSL encryption in transit
  • ISO 27001-certified EU data centers
  • DDoS protection & rate limiting
  • Geo-redundant backups
Access & Authentication
  • Multi-factor authentication (MFA) on all systems
  • Role-based access control (RBAC)
  • Principle of least privilege
  • Full audit logging of all access
  • Tenant-level data separation
AI & Data Privacy
  • Personal data masked before any LLM processing
  • No AI training on customer data, ever
  • EU-region Azure OpenAI deployment
  • Bring Your Own LLM option available
  • On-premises storage option available
Processes & Organisation
  • DPA with every customer & all subprocessors
  • Regular employee security training
  • Incident notification to customer < 24 hours
  • Annual penetration tests by external security firms
  • DPIA per Article 35 GDPR
  • Regular internal security reviews

Completing the DPA: Two Options

RecommendedRequest online
1
Fill out the form: Enter your company details directly in the online form.
2
DPA is generated: Your personalized DPA is created automatically.
3
Sign digitally: You receive the DPA via email and can sign it directly online.
Complete manually
1
Download: Get the DPA in your preferred language.
2
Sign: Digitally or by hand. The signatory must be authorized to represent the company.
3
Email: Send the signed copy to privacy@sally.io. We countersign within 1–3 business days.

Documents & Resources

📄
Data Processing Agreement (DPA)

GDPR-compliant DPA under Art. 28, signed with every customer. Available in English and German.

Download DPA
🔒
Technical & Org. Measures (TOMs)

Our full technical and organizational security measures. Annex 1 of the DPA.

Download TOMs
🌐
Subprocessors List

All subprocessors with processing purpose and EU hosting location. Annex 3 of the DPA.

Download List

Contact

Data Protection Officer
Norton Engele